The domain dl.downb468.com is registered by proxy through GODADDY.COM, LLC and was originally registered in August of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Massachusetts, United States (US)
Create date:
Wednesday, August 28, 2013
Expires date:
Friday, August 28, 2015
Updated date:
Friday, August 29, 2014
ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.FIRSERIASL.Q, PUP.Installer.AppsInstallerSL.Q, PUP.Installer.EilioDevelopmentssl.R, PUP.FIRSERIASL.Q, PUP.Solimba.FIRSERIA.Bundler (M), PUP.Solimba.EilioDev.Installer (M), PUP.Solimba.RAPIDDOW (M), PUP.Solimba (M)
100.00%
VIPRE Antivirus
DownloadMR, Threat.4150696
10.34%
Dr.Web
Trojan.DownLoader11.4341, Trojan.DownLoader11.24441, Adware.Downware.1433
10.34%
Malwarebytes
PUP.Optional.AppsInstaller, PUP.Optional.Solimba, PUP.Optional.FirSeriaInstaller
10.34%
NANO AntiVirus
Trojan.Win32.DownLoader11.cykqpy, Trojan.Win32.Morstar.dfgpqs, Trojan.Win32.Downware.ctidvo
10.34%
Kaspersky
not-a-virus:AdWare.Win32.Fiseria, not-a-virus:Downloader.Win32.Morstar, not-a-virus:Downloader.Win32.Firser
10.34%
Comodo Security
Application.Win32.FirseriaInstaller.IFA, Application.Win32.Solimba.LSW, Application.Win32.Solimba.J
10.34%
Sophos
Solimba Installer, PUA 'Solimba Installer'
10.34%
Avira AntiVirus
APPL/Firseria.A.20, APPL/Firseria.Gen8, TR/Crypt.ULPM.Gen
10.34%
G Data
Win32.Application.Morstar, Gen:Variant.Application.Bundler.Kazy.132995, Gen:Application.Bundler.Firseria
10.34%
Vba32 AntiVirus
Downware.Morstar
10.34%
AVG
BundleApp, Adware BundleApp_r.AV, Adware AdInstaller.Firseria
10.34%
Panda Antivirus
Trj/Genetic.gen, Trj/CI.A, Adware/Firseria
10.34%
IKARUS anti.virus
PUA.Downloader.AppsInstall, AdWare.BundleApp, PUA.FirseriaInstaller
10.34%
avast!
Win32:Adware-BQN [Trj], Win32:Firseria-A [PUP]
6.90%
The domain dl.downb468.com has been seen to resolve to the following 8 IP addresses.
a23-62-7-25.deploy.static.akamaitechnologies.com
January 9, 2015
a23-62-7-51.deploy.static.akamaitechnologies.com
January 9, 2015
a184-51-126-43.deploy.static.akamaitechnologies.com
December 2, 2014
a184-51-126-65.deploy.static.akamaitechnologies.com
December 2, 2014
a23-0-160-11.deploy.static.akamaitechnologies.com
September 28, 2014
a23-0-160-17.deploy.static.akamaitechnologies.com
September 28, 2014
a23-67-243-41.deploy.static.akamaitechnologies.com
January 6, 2014
File downloads found at URLs served by dl.downb468.com.
The following 101 files have been seen to comunicate with dl.downb468.com in live environments.
URL:
http://dl.downb468.com/